Find out what the assessor will find, two weeks before they do.
A fixed-scope technical audit of your cloud environment, delivery pipeline, or data platform against the framework you are being held to. You get a written control mapping, a prioritized list of findings with the architectural fix for each, and an effort estimate per item. The report is yours whether or not you ever hire us again.
Written report · roadmap · effort estimates
Why teams start here.
Nobody hands a stranger a six-figure infrastructure project on the strength of a discovery call. The audit exists so you do not have to. It is small enough to approve without a committee, short enough to finish before your next milestone, and it produces something concrete regardless of what you do next.
It also solves the harder problem, which is that most teams cannot scope their own remediation. They know something is wrong, they do not know how much, and every vendor proposal they receive is priced against a guess. Two weeks of engineering replaces that guess with a document your team, your CFO, and your assessor can all read.
Roughly half of audit clients do the remediation themselves. That is a fine outcome. We would rather you have an accurate roadmap you execute in-house than an inaccurate one that turns into an engagement neither of us enjoys.
What you receive.
Control mapping
Every relevant control mapped to what your system actually does, with the specific CFR section, 800-53 family, or trust services criterion it answers to.
Prioritized findings
What fails, ranked by the order an assessor will hit it, with the architectural fix for each. Written for engineers, not for a binder.
Effort estimates
Engineer-days per finding so you can budget the remediation, sequence it against your roadmap, or price it out to a vendor.
Evidence gap list
What your system currently cannot prove. Usually the most uncomfortable section, and the one that saves the most time later.
How the two weeks run.
We look at the system, not the documentation.
- Read-only access to cloud accounts, pipeline, and IaC
- Architecture and data flow walkthrough with your engineers
- Evidence pull: logs, retention, identity, access history
- Two working sessions, roughly 90 minutes each
We write it up and walk you through it.
- Control mapping and findings drafted
- Effort estimates attached to each item
- Live readout with your team, questions answered
- Final written report delivered
Frameworks we audit against.
You name the framework and the target. We map to it.
What happens after.
Three things typically follow, and we are genuinely indifferent between the first two. You execute the roadmap in-house with the estimates as your plan. You take it to another vendor and get accurate bids against a real scope instead of a guess. Or you engage us for the build, in which case the audit findings become the statement of work and we start from a scope both sides already agree on.
Build engagements run 8 to 12 weeks at $50,000 to $100,000 fixed fee, and teams with ongoing obligations often move onto a continuous compliance retainer after handoff. See the full practice list for what that covers.
Questions.
What do I actually receive?
Do I have to hire you for the remediation?
What does it cover, and what does it not?
Is this a certification or a formal assessment?
What if my environment is bigger than 20 services?
How quickly can you start?
Book a scoping call.
Thirty minutes. Bring your architecture and your deadline. We will confirm the audit is the right starting point, scope it against your actual environment, and send a written proposal within 48 hours. If you do not need an audit, we will tell you on the call.
Book a 30-minute scoping call →